Copy over sshd config.
This commit is contained in:
		
							parent
							
								
									d13e235879
								
							
						
					
					
						commit
						e5d3afc7b8
					
				| @ -2,3 +2,4 @@ os_flavor: "freebsd" | ||||
| zfs_snapshot_datasets: | ||||
|   - zroot/freebsd/computer/be/default | ||||
| sshd_enabled: true | ||||
| sshd_conf: "sshd_config" | ||||
|  | ||||
							
								
								
									
										122
									
								
								ansible/roles/sshd/files/sshd_config
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										122
									
								
								ansible/roles/sshd/files/sshd_config
									
									
									
									
									
										Normal file
									
								
							| @ -0,0 +1,122 @@ | ||||
| #	$OpenBSD: sshd_config,v 1.104 2021/07/02 05:11:21 dtucker Exp $ | ||||
| #	$FreeBSD$ | ||||
| 
 | ||||
| # This is the sshd server system-wide configuration file.  See | ||||
| # sshd_config(5) for more information. | ||||
| 
 | ||||
| # This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin | ||||
| 
 | ||||
| # The strategy used for options in the default sshd_config shipped with | ||||
| # OpenSSH is to specify options with their default value where | ||||
| # possible, but leave them commented.  Uncommented options override the | ||||
| # default value. | ||||
| 
 | ||||
| # Note that some of FreeBSD's defaults differ from OpenBSD's, and | ||||
| # FreeBSD has a few additional options. | ||||
| 
 | ||||
| #Port 22 | ||||
| #AddressFamily any | ||||
| #ListenAddress 0.0.0.0 | ||||
| #ListenAddress :: | ||||
| 
 | ||||
| #HostKey /etc/ssh/ssh_host_rsa_key | ||||
| #HostKey /etc/ssh/ssh_host_ecdsa_key | ||||
| #HostKey /etc/ssh/ssh_host_ed25519_key | ||||
| 
 | ||||
| # Ciphers and keying | ||||
| #RekeyLimit default none | ||||
| 
 | ||||
| # Logging | ||||
| #SyslogFacility AUTH | ||||
| #LogLevel INFO | ||||
| 
 | ||||
| # Authentication: | ||||
| 
 | ||||
| #LoginGraceTime 2m | ||||
| #PermitRootLogin no | ||||
| #StrictModes yes | ||||
| #MaxAuthTries 6 | ||||
| #MaxSessions 10 | ||||
| 
 | ||||
| #PubkeyAuthentication yes | ||||
| 
 | ||||
| # The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2 | ||||
| # but this is overridden so installations will only check .ssh/authorized_keys | ||||
| AuthorizedKeysFile	.ssh/authorized_keys | ||||
| 
 | ||||
| #AuthorizedPrincipalsFile none | ||||
| 
 | ||||
| #AuthorizedKeysCommand none | ||||
| #AuthorizedKeysCommandUser nobody | ||||
| 
 | ||||
| # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts | ||||
| #HostbasedAuthentication no | ||||
| # Change to yes if you don't trust ~/.ssh/known_hosts for | ||||
| # HostbasedAuthentication | ||||
| #IgnoreUserKnownHosts no | ||||
| # Don't read the user's ~/.rhosts and ~/.shosts files | ||||
| #IgnoreRhosts yes | ||||
| 
 | ||||
| # Change to yes to enable built-in password authentication. | ||||
| #PasswordAuthentication no | ||||
| #PermitEmptyPasswords no | ||||
| 
 | ||||
| # Change to no to disable PAM authentication | ||||
| #KbdInteractiveAuthentication yes | ||||
| KbdInteractiveAuthentication no | ||||
| 
 | ||||
| # Kerberos options | ||||
| #KerberosAuthentication no | ||||
| #KerberosOrLocalPasswd yes | ||||
| #KerberosTicketCleanup yes | ||||
| #KerberosGetAFSToken no | ||||
| 
 | ||||
| # GSSAPI options | ||||
| #GSSAPIAuthentication no | ||||
| #GSSAPICleanupCredentials yes | ||||
| 
 | ||||
| # Set this to 'no' to disable PAM authentication, account processing, | ||||
| # and session processing. If this is enabled, PAM authentication will | ||||
| # be allowed through the KbdInteractiveAuthentication and | ||||
| # PasswordAuthentication.  Depending on your PAM configuration, | ||||
| # PAM authentication via KbdInteractiveAuthentication may bypass | ||||
| # the setting of "PermitRootLogin without-password". | ||||
| # If you just want the PAM account and session checks to run without | ||||
| # PAM authentication, then enable this but set PasswordAuthentication | ||||
| # and KbdInteractiveAuthentication to 'no'. | ||||
| #UsePAM yes | ||||
| 
 | ||||
| #AllowAgentForwarding yes | ||||
| #AllowTcpForwarding yes | ||||
| #GatewayPorts no | ||||
| #X11Forwarding yes | ||||
| #X11DisplayOffset 10 | ||||
| #X11UseLocalhost yes | ||||
| #PermitTTY yes | ||||
| #PrintMotd yes | ||||
| #PrintLastLog yes | ||||
| #TCPKeepAlive yes | ||||
| #PermitUserEnvironment no | ||||
| #Compression delayed | ||||
| #ClientAliveInterval 0 | ||||
| #ClientAliveCountMax 3 | ||||
| #UseDNS yes | ||||
| #PidFile /var/run/sshd.pid | ||||
| #MaxStartups 10:30:100 | ||||
| #PermitTunnel no | ||||
| #ChrootDirectory none | ||||
| #UseBlacklist no | ||||
| #VersionAddendum FreeBSD-20211221 | ||||
| 
 | ||||
| # no default banner path | ||||
| #Banner none | ||||
| 
 | ||||
| # override default of no subsystems | ||||
| Subsystem	sftp	/usr/libexec/sftp-server | ||||
| 
 | ||||
| # Example of overriding settings on a per-user basis | ||||
| #Match User anoncvs | ||||
| #	X11Forwarding no | ||||
| #	AllowTcpForwarding no | ||||
| #	PermitTTY no | ||||
| #	ForceCommand cvs server | ||||
| @ -1,3 +1,15 @@ | ||||
| - name: Install Configuration | ||||
|   when: sshd_conf is defined | ||||
|   copy: | ||||
|     src: "files/{{ sshd_conf }}" | ||||
|     dest: "{{ item }}" | ||||
|     mode: 0644 | ||||
|     owner: root | ||||
|     group: wheel | ||||
|   notify: restart sshd | ||||
|   loop: | ||||
|     - /etc/ssh/sshd_config | ||||
| 
 | ||||
| - import_tasks: tasks/freebsd.yaml | ||||
|   when: 'os_flavor == "freebsd"' | ||||
| 
 | ||||
|  | ||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user
	 Tom Alexander
						Tom Alexander